首页> 外文会议>International Conference on Cyber Situational Awareness, Data Analytics and Assessment >Enhancing Cyber Situational Awareness: A New Perspective of Password Auditing Tools
【24h】

Enhancing Cyber Situational Awareness: A New Perspective of Password Auditing Tools

机译:增强网络态势感知:密码审核工具的新视角

获取原文

摘要

Password auditing can enhance the cyber situational awareness of defenders, e.g. cyber security/IT professionals, with regards to the strength of text-based authentication mechanisms utilized in an organization. Auditing results can proactively indicate if weak passwords exist in an organization, decreasing the risks of compromisation. Password cracking is a typical and time-consuming way to perform password auditing. Given that defenders perform password auditing within a specific evaluation timeframe, the cracking process needs to be optimized to yield useful results. Existing password cracking tools do not provide holistic features to optimize the process. Therefore, the need arises to build new password auditing toolkits to assist defenders to achieve their task in an effective and efficient way. Moreover, to maximize the benefits of password auditing, a security policy should be utilized. Currently the efforts focus on the specification of password security policies, providing rules on how to construct passwords. This work proposes the functionality that should be supported by next-generation password auditing toolkits and provides guidelines to drive the specification of a relevant password auditing policy.
机译:密码审计可以增强网络态势的防守意识,例如网络安全/ IT专业人员关于组织中使用的基于文本的身份验证机制的强度。审计结果可以主动表明组织中存在弱密码,降低妥协的风险。密码开裂是执行密码审核的典型和耗时的方式。鉴于捍卫者在特定的评估时间表内执行密码审核,需要优化开裂过程以产生有用的结果。现有的密码开裂工具不提供整体功能以优化该过程。因此,需要建立新的密码审计工具包,以帮助防守者以有效和有效的方式实现自己的任务。此外,为了最大限度地提高密码审计的好处,应使用安全策略。目前,努力侧重于密码安全策略的规范,为如何构建密码提供规则。这项工作提出了由下一代密码审计工具包支持的功能,并提供指南,以推动相关密码审核策略的规范。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号